Heights Consulting Group

Somebody asked who owns security, and there was no answer

An auditor, a board member or an insurer asked for the name of the person accountable for security. What the question is really testing, and what to put in place before it is asked again.

What to do first

What it is
Your customer applying their vendor risk process to your organization.
What it needs
Answers that are accurate within a stated scope, and evidence behind them.
Who owns it
One accountable person, working from what the systems actually do.

The short answer

What you are holding

The question is not asking who does the security work. It is asking who is answerable for whether the work is the right work, and that has to be one named person with the authority to decide and the standing to report. Tooling, providers and a capable IT team do not answer it.

The document

What it is, plainly

It arrives as a single line in a longer conversation: who is responsible for information security here. An auditor asks it because most frameworks require a named owner. A board member asks it after reading about somebody else's breach. An insurer asks it because the answer predicts everything else on the application.

What makes it uncomfortable is that most organizations can describe the work in detail and still not produce a name. Patching happens, backups run, a provider monitors alerts, and every one of those has an owner. The program that decides whether those are the right activities in the right order usually does not.

The question is rarely hostile. It is a structural check, and the person asking already expects that responsibility sits somewhere specific rather than being distributed across a team, a vendor and a spreadsheet.

Consequence

What your answers commit you to

  • Diffused responsibility is the finding

    When several people hold a piece and nobody holds the whole, the gaps sit precisely in the seams between them. That is a governance observation, and it is written up as one.

  • Doing the work is not owning it

    An IT team executing competently and a provider delivering to contract are both necessary and neither is accountable for the program. Ownership is deciding what gets done and standing behind the decision.

  • The name has to carry authority

    Naming somebody without the standing to set priorities, override a project or bring a risk to the board creates a title rather than an owner, and the next auditor will say so.

Before you reply

What to establish first

In this order. Each one narrows what the next has to decide.

  1. Write down who decides what today

    Not the org chart. Who actually chooses which risks get funded, which exceptions are granted, and which projects wait. It is often several people who have never compared notes.

  2. Separate doing from deciding

    List the security activities running now and mark each one as executed by, and decided by. The decided-by column is usually where the blanks are, and it is the column the question was about.

  3. Find where the obligation lands

    Regulation, contracts and insurance policies frequently name a role or require an accountable individual. Those documents often answer the question for you, and disagreeing with them is expensive.

  4. Name one person, in writing

    One name, with the decisions they hold, the authority that comes with them, and who they report to. Two names is the same answer as none.

  5. Give the role something to report

    Ownership is only visible through reporting. A standing item at leadership level, with a short written record, is what turns a name into evidence that somebody is accountable.

  6. Decide how the role is filled

    Internally, by a full-time hire, or by an external CISO-level engagement. All three are legitimate answers, and the question is asking that a choice has been made rather than which one.

Failure modes

Where responses go wrong

Naming the IT manager by default
It puts the person who builds and runs the systems in charge of assessing whether they are adequate. The conflict is structural rather than personal, and an assessor will identify it immediately.
Answering with a committee
A security steering group is useful and is not an owner. Committees advise and share; accountability does not divide, and the question specifically asks for the part that cannot.
Pointing at the provider
A managed provider is accountable to its contract, not to your regulator, your board or your customers. That obligation has never moved and cannot be outsourced.
Creating a title with no authority
Somebody is designated, given no budget, no mandate to say no, and no route to leadership. The role exists on paper and the same gaps persist, which is worse than the honest answer.
Treating it as a hiring question
The conversation goes straight to whether a full-time security executive is affordable, which stalls it indefinitely. What is required first is the decision about accountability.

Referenced

What the questions usually cite

  • NIST CSF Any organization wanting a defensible, comparable baseline. Frequently requested by customers and insurers as a reference point.
  • ISO 27001 Organizations whose customers or markets expect a certified management system, often alongside or instead of SOC 2.
  • SOX Public companies, and private companies preparing for a public offering or an acquirer's diligence.

After

Where this leads

  • Once one person holds it, the sequencing question becomes answerable: what matters most, what waits, and what the organization has consciously decided not to do. That is the difference between a program and a list of activities.
  • It usually surfaces work that was already needed and unowned, which is uncomfortable at first and is the point. Findings without an owner are the ones that reappear in the same form the following year.
  • The reporting rhythm is what most changes leadership's experience. Security stops being a subject that arrives as bad news and becomes a standing item with a trajectory.

Where Heights fits

If you would rather not work it out alone

Heights holds the accountable role. Not advice delivered to somebody who then has to decide alone, but the CISO-level function itself: setting priorities, making and recording risk decisions, and reporting to leadership in terms a board can act on. It is the answer to the question, in a form an auditor, an insurer and a customer all recognize.

Schedule a Confidential Consultation Read about vCISO leadership

FAQ

Questions this raises

Broader questions about executive security leadership are answered on the vCISO page.

Can we name our IT manager and move on?

It is the most common answer and the one most likely to be challenged, because it asks the person accountable for running the systems to also judge whether they are good enough. Assessors treat that as a separation-of-duties issue rather than a comment on anyone's competence.

Where an internal person is the right answer, what makes it hold is authority and reporting line: the ability to set priorities, to say no to a project, and to raise something at leadership level without going through the function being assessed.

What does accountable actually mean in this context?

It means one person answers for the state of the program: whether the risks are understood, whether the priorities are right, and whether leadership has been told the truth about both. It does not mean they perform the work or that they are blamed for an incident.

The practical test is whether that person could be asked, in front of the board, why a particular risk is still open, and give an answer that reflects a decision somebody actually made.

Our provider says they handle security. Why is that not ownership?

Because their accountability runs to their contract and yours runs to your regulator, your customers and your board. A provider can be excellent and still have no view of the obligations that bind your organization or the risks leadership has chosen to accept.

The two fit together well once the boundary is written down. What does not work is treating the contract as though it transferred the obligation, because no contract does that.

How quickly can this be answered properly?

Naming an owner and writing down what they decide is quick, and it is most of what the question was testing. Building the reporting and the risk record that make the role visible takes longer, and it can run in parallel.

What is not advisable is waiting until a full program exists before naming anybody. The absence of a name is the finding, and it is the part that can be closed first.

Insights

Related reading

  • Governance

    What Current Regulation Requires Around Security Program Assessment

    Federal regulations mandate regular security assessments for organizations handling controlled unclassified information (CUI) and federal systems. Executives are accountable for demonstrating that security controls are implemented correctly and operating as intended, but many organizations lack clear ownership of the assessment process. This guide explains the regulatory requirements, what leadership must oversee, and how to establish accountability.